# toolbag-plugin-nsp-check

> toolbag plugin that checks your dependencies against the Node Security Project

Latest version **1.0.0** (published 2016-06-07) · MIT license · 0 weekly downloads

## Install

```sh
npm install toolbag-plugin-nsp-check
pnpm add toolbag-plugin-nsp-check
yarn add toolbag-plugin-nsp-check
bun add toolbag-plugin-nsp-check
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2016-06-07 |
| First published | 2016-06-03 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=4.0.0 |
| Dependencies | 2 |
| Known vulnerabilities | 0 (+2 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 0 |
| Author | Continuation Labs |
| Maintainers | cjihrig |
| Keywords | toolbag, plugin, toolbag plugin, nsp, security, check |

## Links

- npm: https://www.npmjs.com/package/toolbag-plugin-nsp-check
- Repository: https://github.com/continuationlabs/toolbag-plugin-nsp-check
- Issues: https://github.com/continuationlabs/toolbag-plugin-nsp-check/issues
- npm.io page: https://npm.io/package/toolbag-plugin-nsp-check

## Dependencies (2)

- [nsp](https://npm.io/package/nsp.md) 2.4.0
- [lodash.merge](https://npm.io/package/lodash.merge.md) 4.4.0

## Alternatives

- [@openai/codex-sdk](https://npm.io/package/@openai/codex-sdk.md) — 731.4K weekly downloads
- [babel-plugin-transform-react-jsx](https://npm.io/package/babel-plugin-transform-react-jsx.md) — 565.0K weekly downloads
- [babel-helper-remove-or-void](https://npm.io/package/babel-helper-remove-or-void.md) — 508.5K weekly downloads
- [@pnpm/store-controller-types](https://npm.io/package/@pnpm/store-controller-types.md) — 186.9K weekly downloads
- [react-native-signature-canvas](https://npm.io/package/react-native-signature-canvas.md) — 155.6K weekly downloads

## Recent versions

- 1.0.0 (latest) — 2016-06-07
- 0.1.0 — 2016-06-03

## README

# toolbag-plugin-nsp-check

[![Current Version](https://img.shields.io/npm/v/toolbag-plugin-nsp-check.svg)](https://www.npmjs.org/package/toolbag-plugin-nsp-check)
[![Build Status via Travis CI](https://travis-ci.org/continuationlabs/toolbag-plugin-nsp-check.svg?branch=master)](https://travis-ci.org/continuationlabs/toolbag-plugin-nsp-check)
![Dependencies](http://img.shields.io/david/continuationlabs/toolbag-plugin-nsp-check.svg)

[![belly-button-style](https://cdn.rawgit.com/continuationlabs/belly-button/master/badge.svg)](https://github.com/continuationlabs/belly-button)

[Toolbag](https://github.com/continuationlabs/toolbag) plugin that checks your dependencies against the Node Security Project's known vulnerabilities database. Checks against the NSP API can be made at startup time, or at any point during runtime via the toolbag command `nsp-check`.

## Supported Parameters

- `checkOnRegister` (boolean) - If `true`, the NSP API is checked on plugin registration. Otherwise, the `nsp-check` command must be explicitly invoked. Defaults to `true`.
- `packagePath` (string) - The `package.json` file to check. Defaults to `package.json` in `process.cwd()`. This value is passed directly to the `nsp` module.
- `shrinkwrapPath` (string) - The `npm-shrinkwrap.json` file to check. Defaults to `npm-shrinkwrap.json` in `process.cwd()`. This value is passed directly to the `nsp` module.
- `formatter` (string or function) - If this is a string, it can be any formatter supported by `nsp` (`'json'`, `'summary'`, etc.). If this is a function, it will be used to format NSP API output. Defaults to the `nsp` default format.

### Example Configuration

Add `toolbag-plugin-nsp-check` to your `package.json`. Configure the plugin in `.toolbagrc.js` as shown below.

```javascript
'use strict';

const NspCheck = require('toolbag-plugin-nsp-check');
const Path = require('path');

module.exports = function config (defaults, callback) {
  callback(null, {
    plugins: [
      {
        plugin: NspCheck,
        options: {
          checkOnRegister: true,
          packagePath: Path.join(process.cwd(), 'package.json')
        }
      }
    ]
  });
};
```

---
_Source: https://npm.io/package/toolbag-plugin-nsp-check · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
